🚨 ACTIVE EXPLOITATION
- Hackers abuse ViPNet update mechanism to target Russian government agencies — BleepingComputer
Hackers are exploiting ViPNet software updates to attack Russian government organizations.- Targets Russian organizations including government, energy, transport, education, and logistics sectors
- Abuses ViPNet private networking product suite update mechanism to deploy malware
- Malicious DLL (wtsapi32.dll, HelloInjector) sideloaded via legitimate ViPNet updater process
- Malware includes proxy, backdoor, reconnaissance, and log-cleaning modules
- Attributed with low confidence to a Chinese-speaking APT group based on weak indicators
🕵️ RESEARCH & DEEP DIVES
- Hikvision cameras targeted by scans probing Intelligent Security API endpoints — SANS ISC
Hikvision cameras are being scanned for their Intelligent Security API to identify vulnerable devices.- Applies to Hikvision cameras with the Intelligent Security API (ISAPI) since at least 2018
- Scans target the /ISAPI/System/status endpoint to profile devices and check API support
- ISAPI uses Basic or Digest authentication and supports XML/JSON messages
- Encryption with AES is ineffective if Basic authentication is used due to exposed IV and password transmission
- Scans likely aim to brute force passwords by identifying ISAPI-enabled devices